CVE-2017-2297
Summary
| CVE | CVE-2017-2297 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-01 22:29:00 UTC |
| Updated | 2022-01-24 16:46:00 UTC |
| Description | Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issue has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1. This only affects users with labeled tokens, which is not the default for tokens. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Puppet | All | All | All | All |
| Application | Puppet | Puppet | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet | 2017.1.1 | All | All | All |
| Application | Puppet | Puppet | All | All | All | All |
| Application | Puppet | Puppet | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet | 2017.1.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | All | All | All | All |
| Application | Puppet | Puppet Enterprise | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-2297 - Incorrect Credential Management with Labeled RBAC Tokens | Puppet.com | CONFIRM | puppet.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.